No more typing reviews! Try our Samantha, our new voice AI agent.

AlienVault OSSIM vs Devo comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AlienVault OSSIM
Ranking in Security Information and Event Management (SIEM)
27th
Average Rating
7.4
Reviews Sentiment
7.1
Number of Reviews
31
Ranking in other categories
No ranking in other categories
Devo
Ranking in Security Information and Event Management (SIEM)
18th
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
26
Ranking in other categories
Log Management (18th), IT Operations Analytics (7th), AIOps (13th)
 

Mindshare comparison

As of August 2026, in the Security Information and Event Management (SIEM) category, the mindshare of AlienVault OSSIM is 1.1%, down from 3.1% compared to the previous year. The mindshare of Devo is 1.2%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Devo1.2%
AlienVault OSSIM1.1%
Other97.7%
Security Information and Event Management (SIEM)
 

Featured Reviews

BP
Independent Contractor at a comms service provider with 5,001-10,000 employees
Enables cost-effective security management for small businesses
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implementation. The main area where the AlienVault product was lacking around the 2018 timeframe was in its ability to scale. By pushing it to a cloud-based system, they've largely alleviated scale issues. It's native in Amazon but will also run in Azure. They have worked with cloud service providers to offer enough throughput at a cost reasonable for a corporation. Scaling was their biggest problem, and they've largely conquered those issues.
Usama Khan - PeerSpot reviewer
Team Lead SOC at a tech services company with 51-200 employees
Advanced threat hunting has improved SOC visibility and now supports faster incident response
Devo can improve in how its connectors enhance integration with third-party tools. Devo's architecture works by having you deploy a relay server in the data center of the client side and Devo SIEM is basically on the AWS cloud. There are specific ports which are enabled on the relay server, which are 514 and 13000, 13151, 152. However, when we talk about databases and custom integrations, there are not default ports in the relay server. No default ports are defined. For JDBC drivers, the port number is 1433, but it is not in the relay server. You have to add it manually. For Oracle RDBMS, the port is 1521, and it is also not there by default. I would appreciate more third-party integrations including Fortinet and others. Machine learning models can also be improved. Playbooks in the SOAR can also be improved. Regarding playbooks for automation, we utilize playbooks for automation in SOAR for automated IOC blocking on a firewall, on a web application firewall, on DNS security, etc. The only option for us to run the playbook is to schedule the job for it. However, if I want to manually run the playbook, there is no option for doing so. This needs improvement.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"A very good feature of AlienVault OSSIM is that it has many domains that can be integrated from different solutions."
"The open vault component and the checking of vulnerabilities are the most valuable features, and the page management helps with this, because if you know how your device is vulnerable at least you can do something about it."
"The most valuable features of AlienVault OSSIM are vulnerability assessment, network intrusion detection system, response to critical events, and awareness of the whole network."
"The paid version of the solution has reporting and better scalability options."
"This solution is very stable; it runs on a Linux box, you only interface with it through the GUI, it works behind the scenes, and it has never crashed in the time that I have used it."
"Better than other SIEM solutions because almost everything can be integrated."
"The most valuable features of this solution are the data correlation and vulnerability assessment."
"The solution is free to use."
"With Devo, we can eliminate swivel chair analysis among tools for a streamlined workflow that gives us the most direct path to the root cause."
"The drill-down reports capabilities allow analysts to click on any element in a widget. When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins."
"We can ingest virtually any log source, which is much better than our previous solution."
"The ROI has been great as we could launch it in a few months instead of a couple of years, and when you put all the costs together, it is less to have done it than with the open source approach."
"More than anything, we have seen ROI in the amount of time saved during investigations."
"The most useful feature for us, because of some of the issues we had previously, was the simplicity of log integrations. It's much easier with this platform to integrate log sources that might not have standard logging and things like that."
"Overall, I have no issues with it and my guys love it."
"It centralizes security management within a business, functioning as a core system for a SOC."
 

Cons

"AlienVault OSSIM on-premise version is more difficult to implement than the cloud version. Additionally, they should add integration between several different environments at once and improve their online knowledge base."
"The user interface could be improved."
"ArcSight works better than AlienVault right now."
"We need more dashboards and we need more customization for dashboards."
"There needs to be more focus on the NOC and IIS in terms of developing applications for behavior detection."
"AlienVault OSSIM failed to provide our company a full insight, while also giving out a lot of false positives."
"The initial setup was a bit complex. You've got to do a lot of reading. It's not an intuitive implementation."
"The biggest thing I always complain about is that the user intake is a very old version."
"The tools in Devo's active ports need enhancement in their investigative capabilities."
"There are some issues from an availability and functionality standpoint, meaning the tool is somewhat slow. There were some slow response periods over the past six to nine months, though it has yet to impact us terribly as we are a relatively small shop. We've noticed it, however, so Devo could improve the responsiveness."
"Some basic reporting mechanisms have room for improvement. Customers can do analysis by building Activeboards, Devo’s name for interactive dashboards. This capability is quite nice, but it is not a reporting engine. Devo does provide mechanisms to allow third-party tools to query data via their API, which is great. However, a lot of folks like or want a reporting engine, per se, and Devo simply doesn't have that. This may or may not be by design."
"One improvement area for Devo could be simplifying some configuration and improving the onboarding for new analysts because it is quite complex for fresher or new analysts who are handling Devo."
"We only use the core functionality and one of the reasons for this is that their security operation center needs improvement."
"From our experience, the Devo agent needs some work. They built it on top of OS Query's open-source framework. It seems like it wasn't tuned properly to handle a large volume of Windows event logs. In our experience, there would definitely be some room for improvement. A lot of SIEMs on the market have their own agent infrastructure. I think Devo's working towards that, but I think that it needs some improvement as far as keeping up with high-volume environments."
"However, the incident and threat detection is not what we had hoped for."
"There's room for improvement within the GUI. There is also some room for improvement within the native parsers they support. But I can say that about pretty much any solution in this space."
 

Pricing and Cost Advice

"The price of AlienVault OSSIM is too high sometimes for us to present to our customers. The price should be lower. We are on a three-year license to use the solution. We had to pay extra for the support."
"AlienVault OSSIM is an open-source solution."
"The solution is open source, so it's free to use."
"When comparing AlienVault OSSIM to Microsoft Sentinel, AlienVault OSSIM incurs additional costs due to its licensing price structure. If you are using AlienVault for security purposes at a certain level it can have a higher price point than the current pricing of Microsoft Sentinel."
"The tool's licensing costs are yearly."
"We are using a free version of the solution. If you purchase a license there are more features available but the price is a little high. The solution should be cheaper to allow more customers to be able to afford it."
"AlienVault OSSIM is expensive compared to its competitors."
"The licensing fees for the non-community edition are paid on an annual basis, and there are no costs in addition to this."
"Be cautious of metadata inclusion for log types in pricing, as there are some "gotchas" with that."
"Pricing is based on the number of gigabytes of ingestion by volume, and it's on a 30-day average. If you go over one day, that's not a big deal as long as the average is what you expected it to be."
"Devo was very cost-competitive... Devo did come with that 400 days of hot data, and that was not the case with other products."
"We have an OEM agreement with Devo. It is very similar to the standard licensing agreement because we are charged in the same way as any other customer, e.g., we use the backroom."
"Devo is a hosted or subscription-based solution, whereas before, we purchased QRadar, so we owned it and just had to pay a maintenance fee. We've encountered this with some other products, too, where we went over to subscription-based. Our thought process is that with subscription based, the provider hosts and maintains the tool, and it's offsite. That comes with some additional fees, but we were able to convince our upper management it was worth the price. We used to pay under 10k a year for maintenance, and now we're paying ten times that. It was a relatively tough sell to our management, but I wonder if we have a choice anymore; this is where the market is."
"Devo is definitely cheaper than Splunk. There's no doubt about that. The value from Devo is good. It's definitely more valuable to me than QRadar or LogRhythm or any of the old, traditional SIEMs."
"I'm not involved in the financial aspect, but I think the licensing costs are similar to other solutions. If all the solutions have a similar cost, Devo provides more for the money."
"It's a per gigabyte cost for ingestion of data. For every gigabyte that you ingest, it's whatever you negotiated your price for. Compared to other contracts that we've had for cloud providers, it's significantly less."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
14%
Financial Services Firm
8%
University
7%
Computer Software Company
7%
Financial Services Firm
15%
Construction Company
10%
Outsourcing Company
9%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise8
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise5
Large Enterprise12
 

Questions from the Community

What is your experience regarding pricing and costs for AlienVault OSSIM?
It depends. I would need to review their cost models, but generally, they are on a scaled basis based on throughput usage. Because it's a software as a service solution for their core product for U...
What needs improvement with AlienVault OSSIM?
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implement...
What is your primary use case for AlienVault OSSIM?
This solution is very similar to most of the other MSSPs that you would find out there. When I look at use cases, AlienVault was initially aimed at small to medium businesses. It grew, and that was...
What is your experience regarding pricing and costs for Devo?
The pricing of the product is reasonable if we compare it with other Gartner leading products like Splunk, LogRhythm, Microsoft Sentinel, Google SecOps. Its licensing model is basically on per-day ...
What needs improvement with Devo?
Devo can improve in how its connectors enhance integration with third-party tools. Devo's architecture works by having you deploy a relay server in the data center of the client side and Devo SIEM ...
What is your primary use case for Devo?
I am using Devo myself. Basically, I work at an MSSP, and we provide services to the organization for Security Operation Centers. In our Security Operation Center, we provide the service of SIEM vi...
 

Comparisons

 

Also Known As

OSSIM
No data available
 

Overview

 

Sample Customers

Council Rock School District
United States Air Force, Rubrik, SentinelOne, Critical Start, NHL, Panda Security, Telefonica, CaixaBank, OpenText, IGT, OneMain Financial, SurveyMonkey, FanDuel, H&R Block, Ulta Beauty, Manulife, Moneylion, Chime Bank, Magna International, American Express Global Business Travel
Find out what your peers are saying about AlienVault OSSIM vs. Devo and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.